ubnt kayıtları
ubnt üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %16,7
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-269 Improper Privilege Management2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
61Bu hafta | CVE-2015-9266Silahlaştırılmış | Ubiquiti airOS HTTP(S) unauthenticated arbitrary file uploadui · airmax ac firmware · CWE-22 | Kritik9,8 | — | %74,0 | 5 Eyl 2018 |
35İzleyin | CVE-2017-0934İstismar yok | Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of protection ofubnt · edgeos · CWE-269 | Yüksek8,8 | — | %1,3 | 22 Mar 2018 |
35İzleyin | CVE-2017-0932İstismar yok | Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of validation ubnt · edgeos · CWE-269 | Yüksek8,8 | — | %1,2 | 22 Mar 2018 |
32İzleyin | CVE-2017-0933İstismar yok | Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from a Cross-Site Request Forgery (CSRF) vulnerability.ubnt · edgeos · CWE-352 | Yüksek8,0 | — | %0,5 | 22 Mar 2018 |
29İzleyin | CVE-2018-12591İstismar yok | Ubiquiti Networks EdgeSwitch version 1.7.3 and prior suffer from an improperly neutralized element in an OS command due to lack of protectioubnt · edgeswitch firmware · CWE-78 | Yüksek7,2 | — | %1,9 | 20 Haz 2018 |
18İzleyin | CVE-2017-0913İstismar yok | Ubiquiti UCRM versions 2.3.0 to 2.7.7 allow an authenticated user to read arbitrary files in the local file system.ubnt · ucrm · CWE-732 | Orta4,7 | — | %0,3 | 3 Tem 2018 |
- CVE-2015-926661Bu hafta
Ubiquiti airOS HTTP(S) unauthenticated arbitrary file upload
KritikCVSS 9,8SilahlaştırılmışEPSS %74ui · airmax ac firmware5 Eyl 2018
- CVE-2017-093435İzleyin
Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of protection of
YüksekCVSS 8,8İstismar yokEPSS %1ubnt · edgeos22 Mar 2018
- CVE-2017-093235İzleyin
Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of validation
YüksekCVSS 8,8İstismar yokEPSS %1ubnt · edgeos22 Mar 2018
- CVE-2017-093332İzleyin
Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from a Cross-Site Request Forgery (CSRF) vulnerability.
YüksekCVSS 8,0İstismar yokEPSS %1ubnt · edgeos22 Mar 2018
- CVE-2018-1259129İzleyin
Ubiquiti Networks EdgeSwitch version 1.7.3 and prior suffer from an improperly neutralized element in an OS command due to lack of protectio
YüksekCVSS 7,2İstismar yokEPSS %2ubnt · edgeswitch firmware20 Haz 2018
- CVE-2017-091318İzleyin
Ubiquiti UCRM versions 2.3.0 to 2.7.7 allow an authenticated user to read arbitrary files in the local file system.
OrtaCVSS 4,7İstismar yokEPSS %0ubnt · ucrm3 Tem 2018